Moose anime sites, schools, companies in mass media Latin America is the most prone to cryptocurrency mining, according to data released by a cybersecurity company ESET.
“He cryptojacking is a technique used by cybercriminals mine cryptocurrency without permission, using the processing capabilities of the device one victim -regardless of whether active or inactive – by executing malicious code,” the company said.
The report adds that “lVictims may not know this it happens in the backgroundbut may experience reduced performance, overheating, and increased fan activity (with noticeable noise).”
On Android devices, the workload can even “pump up the battery” and cause physical damage or equipment destruction.
ESETone of the most important firms in proactive threat detection, identified through their telemetry the main sites on which malicious miners are most often detected in the region.
The company emphasized this This threat was very relevant during 2025 and detail about it For example, in July last year, the company compromised more than 3,500 websites carry out illegal mining.
They show which sites in Latin America are most exposed to cryptojacking
ESET clarified that within telemetry data in Latin America for the second half of 2025 Two domain profiles related to the detection of mining scripts were highlighted:
- Sites of “expected” risk– These can be pirate pages, unofficial file downloads and streaming sites. Common characteristics of these sites monetized by cybercriminals are long dwell time, presence of aggressive advertising –malicious advertising– and constant execution of third-party scripts
- Legitimate sites are hacked: for example, schools, small and medium-sized enterprises, local media or any other place that in principle does not pose a particular risk. In these cases, the benefit for attackers is not the time spent by the visitor, but the volume of hacked sites.
In addition, the firm listed that 5 types of sites with the most detections in the region in 2025 there were:
Pirate download sites via torrent / repacks (unofficial downloads): Although these sites can mine directly, they usually show malicious ads that contain a script. These ads are usually very aggressive, with constant pop-ups, and also run third-party scripts.
Examples:
- piratebays.to (34.8%)
- thepiratebay3.to
- thepiratebay2.to
- switchtorrent.org
- fitgirl-repacks.site
Anime/manga: pin long-term consumption environments. Visitors spend a long time reading or watching sections, browsing the site and are used to a constant bombardment of pop-ups. This behavior makes them an ideal location for in-browser hacking.
Examples:
- Parent domain: mangany—.com
- Subdominios con series/anime
- onepiece.manga—-.com
- chainsawman.manga—–.com
- spyfamily.manga—.com
- tokyorevengers.manga—-.com
- onepunchman.manga—–.com
- sololeveling.manga—.com
- boruto.manga—-.com
- snk.manga—-.com
- tensura.manga—-.com
- nagatoro.manga—-.com
- tonikawa.manga—-.com
- shikimori.manga—-.com
- mashle.manga—–.com
education: eAmong the sites with the highest number of detections are also many that are similar to educational institutions (private and public). Colombia, Mexico, Brazil or Argentinaamong other countries. According to discovery history, some of them were used for cryptojacking for two years.
Martina López, Computer Security Researcher, ESET Latin Americastressed that “this type of site is attractive to cyber attackers because of their scale, as the compromise of many small sites with a small number of visits creates revenue.”
And added: “A typical characteristic of this profile is that it had a compromised CMS (WordPress/Plugins, weak credentials, shared hosting) and was thus a victim of JavaScript injection.”
“That is, this is not the intention of the institution, but rather They become victims because of the lack of securityunsupervised or resource-limited websites” he commented.
SMEs and local business: mMany domains are from small legitimate businesses, in various fields such as services, auto parts, metallurgy, logistics and accounting, among others. From ESET, they clarified that it is likely that the site has been compromised by third parties and that the owner does not know that it is on a cryptojacking service.
Examples:
- mar-pla—.com ; ceola—.com.mx
- rvmmo—-.com.ar
- nettocontab—-.com.br
- notebook—-.com.br
- metal—-.prom. no
- dietrich-log—-.com.co
- deauto—-.com
- octopus—.com
- shield—.com.br
- tiagoromasarq—-.com.br
Local media/news: lESET telemetry detections are shown by various regional media and news sites, focusing on Mexico in Brazil.
These types of sites usually attract a lot of traffic, they use announcements monetize as well CMS, chips, plugins and other third-party tools. Although they have more visits, they are not as long as streaming ones, and although they use advertising, they are not as aggressive.
Examples:
- hidalgo.quad—-.com.mx
- tribunarib—-.com.br
- jornalab—-.com.br
- met—-cmx.com
- elacarig—-.com
Given this scenario, ESET shares various specific actions to avoid becoming a victim of cryptocurrency mining:
In the case of users, the firm recommended:
- Keep your operating system and browser updated as many companies exploit known vulnerabilities.
- Use a security solution reliable that detects mining scripts in real-time, both on desktop and mobile devices.
- Beware of sites with excessive pop-ups or invasive ads, especially on unofficial streaming platforms or pirated downloads.
- Close tabs that cause overheating, extreme slowness, or unusual CPU usage, even if the site looks legitimate.
In the case of SME, educational institutions in We recommend ESET media:
- Update your CMS, plugins, and themes and remove unused extensions
- Periodically check your site’s code for suspicious JavaScript injections
- Implement strong passwords and multi-factor authentication for administrative access
- Choose hosting providers with security monitoring and incident support
- Check for third-party scripts and ad networks, as many infections occur through compromised legitimate external services
- Schedule periodic safety reviews
- Restriction of user privileges and access to the administrative panel
- Make frequent backups to be able to quickly restore your site in the event of a hack
- “Cryptocurrency mining is no longer a fringe threat and is no longer limited to illegal sites: today it affects legitimate organizations throughout Latin America and is supported by persistent and quiet companies”, concludes Lopez of ESET Latin America

